Security

Abuse controls

We do not treat browser CORS as a security boundary. A browser honours it; a script or command-line client can send whatever origin it likes. Turnstile, the rate limits, fixed destinations, and validation are the controls that do the real work.

Email construction

If something goes wrong

Any form or client can be paused immediately without deleting its configuration, and re-enabled unchanged. Report a vulnerability to security@submit-kit.com.